Intel

AIKIDO-2025-10074

dompurify is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2025-26791 Published Feb 5, 2025

45

Medium Risk

This Affects:

JAVAdompurify
1.0.0 - 3.2.3
Fixed in 3.2.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to cross-site scripting (XSS) due to a flaw in the DOMPurify.sanitize function. This vulnerability allows attackers to bypass the sanitization process, potentially injecting and executing malicious scripts even when the function is used as intended.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

dompurify is vulnerable to Cross-site Scripting (XSS) in versions 1.0.0 - 3.2.3.

How to fix this

Upgrade the org.webjars.bowergithub.cure53:dompurify library to a patch version.